CyberRota Analysis
AI analysis pending.
CVE
CVE-2008-2803
Severity
MEDIUM
CVSS
6.8
EPSS
3.21%
Chrome Firefox
Original NVD Description
The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non-canonical chrome: URIs, which allows remote attackers to execute arbitrary code via vectors involving third-party add-ons.